CVE-2024-52966
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
Exploited
Not listed
EPSS
0.002
10.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet
Description
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAnalyzer Check your version | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiAnalyzer
Credit
External
Vendor remediation
Please upgrade to FortiAnalyzer version 7.6.1 or above Please upgrade to FortiAnalyzer version 7.4.5 or above Please upgrade to FortiAnalyzer version 7.2.8 or above Please upgrade to FortiManager version 7.6.1 or above Please upgrade to FortiManager version 7.4.5 or above Please upgrade to FortiManager version 7.2.8 or above